Is 360mpGui v1.0.2.3.exe safe?
Forty-two of 75 engines flagged this unsigned, UPX-packed executable, while sandbox evidence recorded malicious activity and possible T1055 process injection.
The sample has extensive corroboration: 42 of 75 engines detected it, including 10 high-trust engines, and a completed sandbox run produced a malicious finding. Its unsigned, packed AutoIt profile, T1055 process-injection evidence, and five YARA matches make accidental detection unlikely.
6ace0ae70ef3b8db3c…cd75754269abd2Recommended next actions
Before running
Do not run it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already ran it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The sample has extensive corroboration: 42 of 75 engines detected it, including 10 high-trust engines, and a completed sandbox run produced a malicious finding. Its unsigned, packed AutoIt profile, T1055 process-injection evidence, and five YARA matches make accidental detection unlikely.
The detection ratio is substantial at 42 of 75 engines, with 10 independent high-trust detections. Labels differ, but Microsoft names Malgent and several engines describe trojan, bot, backdoor, or injector behavior. Runtime evidence includes a malicious sandbox finding and activity mapped to T1055 process injection. Static analysis also shows an unsigned UPX-packed executable with high-entropy code, while five community YARA rules matched, including a known-bad imphash rule. The file's age, prevalence, and lack of a confirmed malicious child are counter-signals, but they are outweighed by the independent engine, runtime, and researcher-rule evidence.
What We Detected
42 of 75 antivirus engines flagged the executable, including 10 high-trust engines. Microsoft reported Trojan:Win32/Malgent!MSR, while DrWeb, NANO-Antivirus, Skyhigh, and others reported backdoor, bot, or injector-related labels. Five YARA rules matched, including MAL_Malware_Imphash_Mar23_1, which identifies a known-bad executable fingerprint.
Threat Behavior
A completed sandbox run produced a malicious finding, and the recorded activity maps to MITRE T1055, indicating possible process injection. The executable is unsigned, UPX-packed, and contains high-entropy code, all of which can conceal its payload. It also wrote temporary files and changed service-related registry values. The observed contacts included Microsoft infrastructure, but the host-reputation check did not cover every recorded domain and IP, so it cannot establish an entirely benign network profile.
What To Do Now
Do not run the executable. Keep endpoint protection enabled, quarantine or remove the file, and scan the system if it was already launched. Review active processes, services, and recent registry changes for signs of persistence or injected activity.
Where this verdict could be wrong4 caveats
- engines.tier1FamilyConsensus.strong=false, so the engines do not converge on one specific family despite broad detection.
- The file is common and long-established: prevalence.uniqueSources=610 and file.ageDays=5189.
- contactedHosts inspected four entries and found zero known-malicious or suspicious hosts, but this does not cover every observed domain and IP.
- droppedChildren.hasMaliciousChild=false, although all nine inspected children have unknown verdicts.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Prevalence records 610 distinct sources over more than 14 years
- No confirmed malicious child among nine inspected dropped files
- No persistence indicator was explicitly recorded
- Four checked contacted hosts had no known-malicious or suspicious cache result
- 42/75 antivirus-engine detections
- 10 high-trust engine detections
- Malicious sandbox finding
- Possible process injection mapped to T1055
- Unsigned UPX-packed executable
- Five YARA rule matches
Quarantine or delete this file and do not execute it. If it has already run, keep endpoint protection enabled and perform a full scan while reviewing processes, services, and registry changes.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete42 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial4 of 24 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete8 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 17MITRE ATT&CK techniques
- 7spawned processes
- 24network contacts
- 40filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Used removable-media replication behaviour that can spread files between devices.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
Moderate concern: Decoded or unpacked concealed content while running.
Moderate concern: Checked the environment for virtualisation or analysis tools.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
360mpGui v1.0.2.3.exe
6ace0ae70ef3b8db3c327172919d5704efd4cc58d5e9d633e4cd75754269abd2
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\file.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
%SAMPLEPATH%\file.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
BootLogo.jpg
C:\Users\<USER>\AppData\Local\Temp\360mpGui\BootLogo.jpg
04Isolated runtime analysis - Written fileObserved
360mpGui
C:\Users\ADMINI~1\AppData\Local\Temp\360mpGui
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostDerived
www.microsoft.com
Saved reputation verdict: safe.
06Contacted-host cross-check - Contacted hostDerived
res.public.onecdn.static.microsoft
Saved reputation verdict: safe.
07Contacted-host cross-check - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox; 1 returned "malicious".
Adversary techniques mapped to the MITRE ATT&CK framework.
- www.microsoft.com
- res.public.onecdn.static.microsoft
- fp2e7a.wpc.phicdn.net
- fp2E7A.wpc.2BE4.phicdn.net
- 204.79.197.203
- a83f:8110:7102:0:88fb:40ad:7102:0
- 20.80.129.13
- 23.40.197.184
- 20.99.132.105
- 20.99.133.109
- 192.229.211.108
- a83f:8110:fce1:b48:324f:e6eb:b8ad:4fe4
- 20.99.186.246
- 20.99.184.37
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GoogleUpdaterInternalService126.0.6441.0\Start
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GoogleUpdaterInternalService126.0.6441.0\ImagePath
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\GPU\AdapterInfo
- C:\Users\<USER>\AppData\Local\Temp\360mpGui\BootLogo.jpg
- C:\Users\ADMINI~1\AppData\Local\Temp\360mpGui
- C:\Users\ADMINI~1\AppData\Local\Temp\360mpGui\360mpGui.ico
- C:\Users\ADMINI~1\AppData\Local\Temp\360mpGui\BootLogo.jpg
- C:\Users\ADMINI~1\AppData\Local\Temp\autA6BA.tmp
- C:\Users\<USER>\AppData\Local\Temp\aut3FDD.tmp
- C:\Users\<USER>\AppData\Local\Temp\qnrjsbb
- C:\Users\<USER>\AppData\Local\Temp\aut42AD.tmp
- C:\Users\<USER>\AppData\Local\Temp\aut436A.tmp
- C:\Users\<USER>\AppData\Local\Temp\aut43D8.tmp
- CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
Files this sample writes at runtime
This file drops 9 children at runtime. None are currently flagged malicious in our cache.
- 963c24c25c3607385df1…0dd80dNever scannednever seen before
- 9c4e43769267eef915a6…29347dNever scannednever seen before
- f7c722bd68277a078ab5…ba1c91Never scannednever seen before
- 95af49e7a45ab8e47883…aaf57dNever scannednever seen before
- 6051d962638de1961ab5…436ff5Never scannednever seen before
- 40b2aa6b908cac91451e…5b5dfdNever scannednever seen before
- 293c152ce3c06368e7c1…2e72dcNever scannednever seen before
- f074d5569bbbc731f33d…e2aa55Never scannednever seen before
- 1445bd45a955e8575643…d8604aNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 8rule hits recorded
- 42 / 75engines flagged
- 610sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 isolated runtime environment classified the observed behavior as malicious.
Verdict inputView chapterProvenanceObservedSourceIsolated runtime analysisObserved at - 02
7 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 03
42 of 75 antivirus engines flagged the file, including Alibaba and alibabacloud.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 04
Scanned file: 360mpGui v1.0.2.3.exe — 6ace0ae70ef3b8db3c327172919d5704efd4cc58d5e9d633e4cd75754269abd2
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\file.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — %SAMPLEPATH%\file.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: BootLogo.jpg — C:\Users\<USER>\AppData\Local\Temp\360mpGui\BootLogo.jpg
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: 360mpGui — C:\Users\ADMINI~1\AppData\Local\Temp\360mpGui
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: www.microsoft.com — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at - 10
Contacted host: res.public.onecdn.static.microsoft — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at
Detection sources at a glance
Category: generic-trojan
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- MAL_Malware_Imphash_Mar23_1
- Sus_Obf_Enc_Spoof_Hide_PE
- upx_largefile
- UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
- UPXv20MarkusLaszloReiser
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Users\<USER>\AppData\Local\Temp\file.exe"PE is packed (high-entropy code or known packer) AND unsigned AND at least one engine flagged it. Packing alone is common in legit software; packing + unsigned + signal is the malware-dropper pattern.
Evidencepackers: UPX v0.89.6 - v1.02 / v1.05 -v1.24 -> Markus & Laszlo [overlay], AutoIt, UTF-8, UPXUnsigned, packed PE with sandbox-observed network activity. The packing step hides the payload until execution; the network call fetches / reports for the next stage. Classic dropper / stager behaviour.
Evidencewww.microsoft.com
42 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
Executable sections have high entropy (7.2+) — the code is compressed or encrypted and only decrypted at runtime. Classic packing behaviour.
Packers compress or encrypt the executable and only unpack it at runtime. Legitimate commercial software uses them too — but if the file is also unsigned and rare, it's a strong malware signal.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- 360mpGui v1.0.2.3.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 2.4 MB
- Last analyzed
- Sep 30, 2026, 1:57 AM UTC
6ace0ae70ef3b8db3c327172919d5704efd4cc58d5e9d633e4cd75754269abd2Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't run this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already ran it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the developer's official site or an official app store.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is 360mpGui v1.0.2.3.exe a virus?
What is 360mpGui v1.0.2.3.exe?
How many antivirus engines detected 360mpGui v1.0.2.3.exe?
What should I do if I already ran 360mpGui v1.0.2.3.exe?
How do I remove 360mpGui v1.0.2.3.exe?
What kind of malware is 360mpGui v1.0.2.3.exe?
What is the SHA-256 hash of 360mpGui v1.0.2.3.exe?
How up to date is this analysis of 360mpGui v1.0.2.3.exe?
Community
Member reviews and reports for this exact file hash.